VYPR

Uflo

by Uflo Project

CVEs (1)

  • CVE-2022-25894CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.03

    All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.